Automatic JIT Approval
Automatic JIT (Just-in-Time) approval allows users to temporarily elevate their permissions when needed, by granting the request instantly, without requiring an Administrator approval to review and respond.
you attempt to perform an application requiring approval, a dialog is presented. You enter a justification and the request is approved. Automatic approvals are recorded as such, indicating System as the Approver in the approval history.
The features of Automatic JIT Approval are:
-
The Automatic JIT Approval Process cannot be modified, deleted, cloned, or replicated.
-
It's available on both Windows and macOS workstations.
-
Even though approval is automatic, a justification is still required from the user, ensuring there's an audit trail of why privileges were requested.
Key Differences from Standard JIT Approval
| Feature | Standard JIT | Automatic JIT |
|---|---|---|
| Requires human approver | yes | no |
| Request starts as | Pending | Approved immediately |
| Approver shown in reports | username | System |
| User wait time | until approved | instant |
Responding to Automatic JIT Approval (User)
When you attempt to launch the application, an approval dialog is presented. Enter a justification Reason and click Continue.
Configuring Automatic JIT Approval (Administrator)
Offline approvals are not supported.
Perform the following steps to enable Automatic JIT Approval.
Automated JIT approval requests are in place for 7 days and do not require additional prompting when accessing the targeted application.
macOS Workstations
-
Create a duplicate of the macOS JIT Admin Privilege Request (Sample) policy.
-
Edit the duplicate policy for the following actions:
-
Remove the macOS JIT Admin Privilege Request Action (Sample) – Approval Request Message Action (HTML) action.
-
Add the macOS JIT Admin Privilege Request Action (Sample) - Automatic Approval Request Message Action (HTML) action.
-
- Save and Enable the policy.
Windows Workstations
-
Create a duplicate of the JIT Mode (Startup and Approval) (Sample) policy.
-
Edit the duplicate policy for the following actions:
-
Remove the Approval Request Form Action action.
-
Add the JIT Approval Request Form Action - Automatic Approval action.
-
-
Save and Enable the policy.
-
Enable the following policies to complete the JIT process:
-
JIT Mode (Sample)
-
JIT Mode (Child Processes) (Sample)
-